The Customer Experience

Section 14 of Agentic Banking Architecture: A Practitioner's Guide

Your bank's next customer won't be human.

Most of this guide covers the inside of the bank. This section is about the edge: how customers interact with their bank once agents arrive. I see four models emerging.

1. Agentic behaviour in the bank's own chatbot

Where most banks are today, and the least interesting model. Chatbots have taken actions for years; making them agentic changes nothing structural. And why would customers use the bank's assistant when they already have an AI for everything else?

2. Bank data exposed to the customer's agent, read-only

In my view this is largely open banking in new clothes: the APIs exist, MCP is a thin adapter on top. What's new is identity: authenticating the agent, the customer, and the binding between them.

3. The customer's agent transacts

The hard step. The tempting solution is scoping, like direct debit mandates: limits, whitelisted payees, revocable authority, step-up authentication outside scope.

I think that's incomplete. A direct debit is deterministic: a human decides once, a machine executes exactly that decision. An agent mandate authorises a probabilistic decision-maker to originate transactions, still exercising judgment within the envelope. Scoping bounds the damage from misplaced trust; it doesn't remove the trust question.

Banking's closest instrument is the discretionary mandate. But its trust isn't in the manager's judgment — it's in the accountability structure around it: a licensed institution, fiduciary duties, recourse when things fail.

That's what agent-initiated transactions are missing: an accountability anchor. When an agent is manipulated into paying a scammer, three parties sit where two used to: customer, bank, AI provider. Banks will argue an agent instruction equals a customer instruction. Regulators won't accept that at scale. In my view, whoever builds the first credible accountability model for agent-initiated payments will shape this market.

Banks have a natural role here: people trust them, and they hold the licences for delegated judgment. A certified "Claude for DBS", built with the AI providers and installed as a skill in the customer's own agent, is one possible solution.

4. The bank provides the agent

Continuously running services: optimise my savings, watch my payments for fraud, find me ways to save.

In governance terms this may be the easiest model, not the hardest: the agent runs inside the bank's perimeter, under its control plane. Regulation also cuts in the bank's favour: continuous investment optimisation is portfolio management, and banks already hold the licences.

If banks don't build these, fintechs will — and banks become product manufacturers behind someone else's customer relationship. Sooner or later, some banks will dare.

The mental model

Grid: who owns the agent (bank or customer) against how much is delegated to it (read and assist, execute on instruction, act on own initiative)

Not a ladder but a grid: who owns the agent (bank or customer) against how much is delegated to it — read and assist, execute on instruction, act on own initiative. The right column is where probabilistic delegation lives, and where the structural change is. The grid also exposes combinations nobody is building yet.

What breaks along the way

Much will break quietly as these models arrive. One example: fraud models are trained on human behaviour, so agent-initiated transactions look anomalous by default. And the social engineering target shifts from persuading the human to injecting the agent — which connects directly to the prompt injection attack surface described in Section 12.

What this leaves out

All of this assumes the customer's agent chooses neutrally. It won't. If agents make the decisions, banks must learn to sell to agents — and that changes product economics in ways most banks haven't priced in. That's a topic for a future section.

This section expands on ideas first published in Part 13 of the LinkedIn series on agentic banking architecture. The accountability anchor framing for agent-initiated transactions — as distinct from a scoping mechanism — emerged from working through why the direct debit analogy fails.